#dataprivacy

Posts mentioning hashtag #dataprivacy

Below are all the posts — topics as well as replies — that mention the hashtag #dataprivacy.

Mention #dataprivacy in your post to continue the discussion!

Texas Protects Your Medical Records. Your Job's Insurance Doesn't.

Texas Protects Your Medical Records. Your Job's Insurance Doesn't.

Somewhere outside the United States, a man with administrative access to an American health insurer's systems is looking at a screen full of patient records. Names. Dates of birth. Member identification numbers. Diagnoses. Years of claims.

He may be at his kitchen table, on home wifi, with his phone beside him. He may be in a windowless facility that took a badge and a fingerprint to enter, where the phone cameras are taped over and nothing reaches the outside internet.

No federal rule distinguishes between those two rooms. None has ever been written.

For nearly three decades, the Health Insurance Portability and Accountability Act has been the public's shorthand for medical privacy, invoked at every pharmacy counter and on every clipboard. What the law says about the physical circumstances in which health
records are actually viewed amounts to a single sentence, and that sentence requires almost nothing.

The provision is 45 CFR 164.310(b). It obliges a covered organization to maintain
policies describing "the physical attributes of the surroundings" of any workstation
that can reach electronic health information. It does not say what those attributes should be. It sets no minimum. It names no control. A secured operations center and a laptop on a sofa satisfy the requirement equally, so long as a document somewhere describes each arrangement.

The rule was written in 2003, when remote access to a health plan's production systems was rare and mostly stationary. It was last substantively amended in 2013. It has not been revisited since the work of maintaining American health data became something that can be done from anywhere on earth with a broadband connection.

What federal law does not require is easier to state than what it does. There is no
requirement for multi-factor authentication on systems holding patient records. No requirement for a controlled or supervised workspace. No restriction on access from a private residence, or from outside the United States, or on privileged administrative access from a foreign country. No prohibition on cameras in the room where records are displayed. And no obligation to tell patients, or even the insurer's own corporate customers, that their records can be reached from abroad.

Each of those decisions belongs entirely to the company. Some organizations impose all of them. Others impose none. Under current law, both are in compliance.

Nor does it matter, legally, who employs the person at the keyboard. Much of the
oversight that does exist was designed around outside vendors: the written agreements a hospital or insurer must sign with a business associate, the assessments it performs before hiring one, the attestations required when a Medicare plan hands work to a subcontractor abroad. None of that machinery engages when the person is on the company's
own payroll.

American insurers and health technology firms have spent two decades building wholly owned subsidiaries overseas, employing tens of thousands of engineers directly. Those engineers are workforce, not business associates. No agreement is required between a company and its own staff. The nationality of the employee is irrelevant to the law, as it should be. What is not irrelevant, and what no rule addresses, is that the entire apparatus of third-party scrutiny simply does not apply to the arrangement that has become the most common one.

There is one exception, and its origin is telling. The strictest rule anywhere in the
country governing where American health records may be handled was not written by a privacy regulator. It was written by a state purchasing office.

Texas requires, through the contract every managed care organization must sign to do business with its health and human services agency, that work be performed and information maintained inside the United States. The same contract bars remote access to the state's systems and data from offshore locations. It does not ask a company to describe its safeguards. It tells the company where the work may happen.

A handful of other states have reached similar conclusions by different routes, several of them through governors' executive orders barring state agencies and their subcontractors from sending work abroad. The restrictions are real, they are enforceable as contract terms, and they demonstrate that the question is neither novel nor unanswerable.

They also reveal the shape of the gap. These rules exist because a state was buying something and could set its terms. They protect the residents of those states, in those programs, and nobody else. A Texan enrolled in Medicaid is covered by a rule that a Texan with employer insurance is not, over the same records, in the same city, held by the same company. The protection follows the contract, not the patient.

There is one federal mechanism that touches the question, and it is regularly mistaken for supervision. Since a series of memoranda issued in 2007 and 2008, Medicare Advantage and prescription dr-g plan sponsors that use offshore subcontractors with access to
beneficiary health information have been required to file an attestation with the
Centers for Medicare and Medicaid Services. The form is more demanding than most people assume. A sponsor must describe the information involved, explain why sending it is necessary, and state what alternatives it considered and why it rejected them.

Then the form is filed, and nothing happens. The agency does not approve it. There is no review, no license, no conditions, and no authority to refuse. A company decides, and then reports what it decided. The requirement also reaches only Medicare plans. For commercial insurance, covering most working Americans, no comparable notification exists at all.

That the government is capable of writing a firmer rule is not in question, because it
recently did, on the same data, in a fraction of the time.

In February 2024, an executive order directed the Justice Department to restrict foreign access to Americans' bulk sensitive personal information. The resulting regulation took effect in April 2025 and became enforceable that July. It names the countries it covers. It sets numerical thresholds: health information on more than 10,000 Americans,
or genetic information on more than 100. It reaches employment and vendor arrangements explicitly, and one of its own published examples treats foreign technical staff with access to encrypted health data as a prohibited transaction. Records stripped of identifying details under HIPAA can still fall within its scope.

Fourteen months, from executive order to binding rule.

The distinction was never the data. It was the framing. Asked whether foreign
adversaries might obtain American medical records, the government wrote an enforceable prohibition in a little over a year. Asked whether patients' medical records are handled carefully, it has produced, in twenty-eight years, one form that nobody reviews.

If any event was going to change that, it should have been what happened at Change Healthcare.

The company processes a substantial share of the nation's medical claims. On February 12, 2024, intruders logged into a remote access portal using stolen credentials. The portal did not require a second form of authentication. They moved through the network
for nine days before anyone noticed. By the time the company confirmed that data had been taken, it was March.

Pharmacies could not fill prescriptions. Physician practices went months without being paid. Congressional committees convened hearings, and the chief executive of the parent company testified that security procedures had not been updated after the 2022 acquisition. The company reported to federal regulators that approximately 192.7 million
people were affected, close to two thirds of the United States population. It is the
largest medical data breach ever recorded.

Two details from the aftermath have drawn less attention than they deserve.

Before the breach, Change Healthcare held a HITRUST certification for its enterprise
infrastructure, an assessment the industry treats as evidence that an organization's
security is sound. The company had publicized it. It was certified, and the portal still
had no second factor of authentication. Certification is the principal way American
health care organizations satisfy themselves that a vendor's environment is adequate, including vendors operating overseas. It did not detect the failure that brought down a third of the nation's claims traffic.

And no federal penalty has been announced. For scale, the largest fine in the history of the medical privacy law remains a $16 million settlement reached in 2018 over a breach affecting 78.8 million people, about twenty cents a record. In the first part of this year, federal regulators closed six enforcement matters with penalties totaling roughly
$1.3 million across all of them.

The formal response to the largest breach in the sector's history was a proposal. In
January 2025, regulators published a draft update to the security rule that would, among other things, require multi-factor authentication. Public comment closed that March. The proposal has not been finalized. The federal regulatory agenda now lists July 2027 as
the target. A second initiative, a set of cybersecurity performance goals, is voluntary.

More than two years on, the missing control that caused the breach is still not required by law.

There is a structural reason none of this has generated sustained pressure, and it is
not indifference. Nobody is counting.

No law obliges a vendor to disclose that it permits access from outside the country, or from employees' homes. A hospital or insurer must have a contract with its business associates, but is not required to know, and often does not know, which country a subcontractor's subcontractor is working from, or what that room looks like. Patients cannot find out. Regulators do not collect the information outside the Medicare program.
Researchers cannot measure what is not recorded. The result is a category of risk that produces no statistics, and policy in the United States rarely moves against risks that produce no statistics.

Every legal obligation in American medical privacy law attaches to the information. Not one attaches to the room.

A health plan is fully responsible for records that an employee of a subsidiary, or a contractor three tiers below it, may be reading on a personal laptop in a country nobody
at the plan could name. No rule requires the plan to know this, to prevent it, or to
tell anyone that it is so.

The law punishes the theft after it happens. About the conditions that would make it easy, it says nothing at all, and has said nothing since 2003.


What will Dell do to secure it's apps/products

Quantum computing can break RSA cryptography. A sufficiently powerful quantum computer will use Shor's algorithm to easily factor large prime numbers, rendering standard public-key infrastructure (PKI), VPNs, and digital signatures useless.The primary business dangers include:

  1. The "Harvest Now, Decrypt Later" ThreatThe danger is not just theoretical or reserved for the future. Malicious actors and nation-states are already intercepting and hoarding encrypted corporate data, waiting for the arrival of cryptographically relevant quantum computers. Any sensitive data with a long shelf-life—such as proprietary IP, medical histories, and financial records—stolen today will eventually be readable.

Washington Post Faces Data Pricing Lawsuit

The Washington Post faces a new class-action lawsuit. It is accused of "surveillance pricing" against subscribers. The lawsuit alleges the paper harvested personal data to set unequal prices. Longtime customers reportedly paid more than new subscribers. The Clarkson Law Firm seeks punitive and statutory damages.

https://www.wfmd.com/2026/06/11/washington-post-faces-class-action-lawsuit-alleging-surveillance-pricing-of-subscribers/


Kyndryl attempted acquisition blocked by Dutch government

The Dutch government has blocked the sale of Solvinity, the company that manages its online services portal DigiD, to the US-based tech giant Kyndryl amid concerns that millions of citizens’ private data could be compromised.

https://www.dutchnews.nl/2026/05/dutch-government-blocks-sale-of-digid-owner-to-us-tech-giant/


Who are we hiring in management?

I’m pretty sure my boss is a re--rd and lacks the judgment and skill set for the role. He has a very childlike mindset and doesn’t seem to understand that putting people’s personal information into AI is a serious violation of trust. I go into work with the best intentions, but my direct manager consistently makes the experience frustrating and unprofessional. Basic decision-making, communication, and common sense seem to be a struggle for him, and it’s hard to see what qualifications or actual expertise got him into the position in the first place. It honestly feels like the rest of the team is constantly compensating for his lack of competence instead of being led by someone capable.

CSSC New York

This is crazy.


SAP's new Company Memory is just data harvesting for SAP AI and for Palantir

Spoke at length with some engineers who are working on this. They are "optimizing" the company memory to work with the Palantir AI program. When did we become beholden to American surveillance companies like this? When data leaks happen or when Palantir sells this data to third parties, this is going to bite SAP in the a$$.


Customer Data Leaks in Corporates via Gong

Been seeing a lot of people bashing Corporates lately, and didn't want to miss out on the fun. I wonder what Corporates Customers and Partners would think of they knew every conversation with a sales rep is recorded, and searchable by anyone in the company.

No, I am not joking. Anyone at any time can search a database of 1000s of hours of meetings, and discover in real time which firm, whether it's KPMG, Deloitte, EY, or Accenture and find out who is working on a new opportunity with a potential or existing client. Taking it one step further, as a result of a simple search, anyone can find out who is involved and timing. There is no data privacy, and no controls on who can access information.

You can't make this stuff up. This is Corporates Leadership for you.

#KPMG #Deloitte" #EY #Accenture #Dataleak


Great privacy news for California residents!!

https://privacy.ca.gov/drop/

California residents can now use the Delete Request and Opt-Out Platform (DROP) to request the deletion of their personal information from over 500 registered data brokers with a single submission. Launched on January 1, 2026, the free tool is operated by the California Privacy Protection Agency and allows users to verify their residency and submit a request to stop brokers from collecting, selling, or sharing their data.

While requests can be submitted immediately, data brokers are not required to begin processing these deletion requests until August 1, 2026. Once processing begins, brokers must delete the specified information within 90 days and are required to check for new requests every 45 days thereafter.

Eligibility: You must be a California resident to use the platform.

Verification: Users verify their identity through the California Identity Gateway or Login.gov.

Exceptions: Brokers are not required to delete publicly available information (e.g., real estate records) or first-party data collected directly from customers.
Enforcement: Failure to comply with deletion requests can result in daily fines, with independent audits starting in January 2028.

Website: The platform is available at privacy.ca.gov/drop/.

Please start protecting your privacy!!


After this round of massive layoffs

It is more and more visible in social media that people get angry and there is also copy paste trend about data protection. People are massively pasting under their random posts on Lnkdn the text:

“Is there a firewall separating OH patient data from your defense and intelligence infrastructure? Yes or no?”
And nobody responds.

Can somebody explain me what is this rumour about?


DD Access change

Noticed they’ve separated onshore and offshore Datadog access.

Is this a response to concerns around PHI and PII exposure offshore? Or is there another operational or compliance reason driving the change?

If anyone in leadership has context on what prompted this decision, it would be great to understand the thinking behind it. Increased data controls are always worth discussing, especially would shape on/offshore future hiring pattern.


DO NOT LET YOUR DEVICE GET LOCKED

After I was told that I was let go, my OT accounts got disabled in around two to two and half hrs. Since I had not locked my device or logged out, I could continue to access my local personal files and upload them to cloud storage. If you have any personal files in Core Share (due to Win 11 migration), upload those immediately as once the OT account is disabled, you can't access those files.

As soon as I locked my session, I could no longer access the laptop because my user profile was disabled, and only the OT Admin can access it now. So, DO NOT LET YOUR DEVICE GET LOCKED till you have all your personal files uploaded.


I work in BTS. Quick heads-up about using Microsoft Copilot for personal stuff.

Here's the deal: anything you type into Copilot on a company device can be logged and stored under our organization's Microsoft 365 tenant. So if you're asking it about that weird rash, your divorce, or your side hustle… just know that's not exactly private.

And I'll be real with you. I'm on the BTS team, and we can see your prompts. All of them. No one's sitting here reading them for fun, but the access is there, and we just want you to be aware.

So do yourself a favor... Use Copilot at work for work things, and save the rest for home.
Easy rule of thumb: if you'd cringe seeing your prompt on a big screen during a team meeting, don't type it on your work laptop. 😅


How is a developer at this company supposed to pivot elsewhere?

I got this job out of college a few years ago and every time someone tells me to jump ship and so on I'm met with the reality that my skills and knowledge have either remained stagnant or actually gotten worse with this company. Combine that with programing in C and I feel like I've been left holding the bag. I need options here before I somehow find myself replaced by an Indian despite being told "Your work is proprietary and cannot be done by offshore employees," as if that's stopped PHI being leaked and exposed for the past several months or turning entire teams into being contractors for Tech Mahindra.


Verizon being called put in congress

Both, Senators J Kennedy and Hawley - calling out VZ for NOT protecting the privacy of customers and handing over data to specific GOP officials with NO question whatsoever. HAtchet man being called out by obe of the senators:
https://www.instagram.com/reel/DUnxKc_EQTw/?igsh=M2xha3I2MDl0Nnlw

They should has told the senator that Dan was too busy drinking coffee and takkng selfies for his said: “baby”


RF has a new gig to keep him busy - TikTok

Now even less time for DXC. The AI bot who wrote the earnings call speech is now the DXC CEO.

TikTok USDS Joint Venture LLC Established in Compliance with U.S. Regulatory Requirements

Today, TikTok USDS Joint Venture LLC has been established in compliance with the Executive Order signed by President Trump on September 25, 2025, now enabling more than 200 million Americans and 7.5 million businesses to continue to discover, create, and thrive as part of TikTok's vibrant global community and experience. The majority American owned Joint Venture will operate under defined safeguards that protect national security through comprehensive data protections, algorithm security, content moderation, and software assurances for U.S. users.
TikTok USDS Joint Venture's mandate is to secure U.S. user data, apps and the algorithm through comprehensive data privacy and cybersecurity measures. It will safeguard the U.S. content ecosystem through robust trust and safety policies and content moderation while ensuring continuous accountability through transparency reporting and third-party certifications.
….
Data Protection: U.S. user data will be protected by USDS Joint Venture in Oracle's secure U.S. cloud environment. The Joint Venture will operate a comprehensive data privacy and cybersecurity program that is audited and certified by third party cybersecurity experts. The program will adhere to major industry standards, including the National Institute of Standards and Technology (NIST) CSF and 800-53 and ISO 27001 as well as the Cybersecurity & Infrastructure Security Agency (CISA) Security Requirements for Restricted Transactions.
Algorithm Security: The Joint Venture will retrain, test, and update the content recommendation algorithm on U.S. user data. The content recommendation algorithm will be secured in Oracle's U.S. cloud environment.
Software Assurance: The Joint Venture will secure U.S. apps through software assurance protocols, and review and validate source code on an ongoing basis, assisted by its Trusted Security Partner, Oracle.
Trust & Safety: The Joint Venture will safeguard the U.S. content ecosystem and have decision-making authority for trust and safety policies and content moderation.
Interoperability enables the Joint Venture to provide U.S. users with a global TikTok experience, ensuring U.S. creators can be discovered and businesses can operate on a global scale. TikTok global's U.S. entities will manage global product interoperability and certain commercial activities, including e-commerce, advertising, and marketing.
The Joint Venture, built on the foundation of the TikTok U.S. Data Security (USDS) organization, will operate as an independent entity governed by the following seven-member, majority-American board of directors:

Raul Fernandez – Independent Director and Chair of the Security Committee: Raul Fernandez is President and Chief Executive Officer of DXC Technology and a member of its Board of Directors. He brings more than three decades of experience at the intersection of technology, risk, and national security.

Full Press Release here: https://newsroom.tiktok.com/announcement-from-the-new-tiktok-usds-joint-venture-llc?lang=en


You cannot make things stuff up: Infosys Collects Remote Work Electricity Data

Infosys has launched an initiative to survey employees about their work-from-home electricity usage. This effort aims to accurately estimate greenhouse gas emissions for environmental reporting. The company's hybrid work model means its environmental footprint extends beyond office campuses. Infosys states the survey is voluntary and for internal assessments and regulatory compliance. This move is part of its long-standing sustainability program.

https://www.latestly.com/technology/infosys-asks-employees-to-share-work-from-home-electricity-usage-data-know-why-7290500.html/amp


This is happening - India and data

https://shublawyers.com/in-the-news/gainwell-technologies-reportedly-exposes-americans-private-information-overseas/

https://news.bloomberglaw.com/health-law-and-business/medicaid-firm-struggles-to-block-patient-data-from-india-workers

Hey DP,
You know we believe your teams in India are doing the same.
Do our customers know this?
Better clean this up.
Keep on sending those jobs to your friends.
This is what happens.


ushq-teamlist cybersecurity email

If you were one of the people that did download the list, I received an email from Cybersecurity letting me know I broke policy by accessing sensitive information. They only asked to respond back to confirm any copies have been deleted, and if you distributed the list, to let them know where you shared it. My director was CCd on the email, but they didn’t think it was a big deal and moved on. There will only be action taken if you don’t respond to the email.


Will Outsourcing so Heavily Lead to Increase in Data Breaches and Identity Theft From Foreign Entities of American Federal Medicare Data???

I believe this is a major concern perhaps being overlooked.

I wonder if the American public or even our government realize how vulnerable transferring sensitive american federal health data across the world globe to another country in the far east.

Please discuss. Maybe not an issue but personally it makes me a little concerned.


HR does not exist

All our HR data is handle by AWS ....really?
Try to contact a human that works in AT&T HR you will never find ....anyone.
They subcontract all to apps or other companies.
We own nothing. Not even a server with our own data.
Good Idea, good implementation from our Bachelor in Arts Jeremy.
Let's hold all data for our network in Amazon Prime.


Another day, another Oracle breach. So many cloudy days at O

Dozens of Oracle customers impacted by Clop data theft for extortion campaign: Researchers said malicious activity dates back to early July and active exploitation was observed two months ago.

Clop, the notorious ransomware group, began targeting Oracle E-Business Suite customers three months ago and started exploiting a zero-day affecting the enterprise platform to steal massive amounts of data from victims as early as Aug. 9, Google Threat Intelligence Group and Mandiant said in a report Thursday.


Humana using Providence Company for “secure” Data Exchange

I can only imagine how many people will experience identity theft as a result of this.

“ LOUISVILLE, Ky.--(BUSINESS WIRE)-- Humana Inc. (NYSE: HUM) and Providence, a Washington-based health system, today announced a pioneering initiative to streamline and secure data exchange between payers and providers – setting a new standard for interoperability in support of value-based care.”

I bet in coming days, we will hear about lawsuits where major data breaches occurred as a result to this. Mark your calendars.


CES is no longer required

A reminder for those waiting for the next CES. Your feedback is being collected in realtime. Employees sentiment is monitored by Aware, an AI service that monitors internal dialogue.
If you were wondering why the CES seems diluted, it is because they already have the data they need

https://www.cnbc.com/amp/2024/02/09/ai-might-be-reading-your-slack-teams-messages-using-tech-from-aware.html